CVE-2026-101264
Received Received - Intake

Command Injection in Ziroom ZHOME A0101

Vulnerability report for CVE-2026-101264, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ziroom zhome 1.0.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a command injection vulnerability in Ziroom ZHOME A0101 1.0.1.0. The issue is in the /api/ZRnetwork/set_passwd endpoint where the password1 parameter is not properly sanitized before being passed to system commands. Attackers can inject malicious shell commands by manipulating this parameter, potentially leading to remote code execution on the device.

Detection Guidance

Check for unauthorized access to the /api/ZRnetwork/set_passwd endpoint. Monitor HTTP POST requests containing the password1 parameter with suspicious payloads like semicolons or command chaining. Inspect logs for os.execute() calls in ZRLanWanFun.lua.

Impact Analysis

An attacker could exploit this to execute arbitrary commands on the device with root privileges. This may allow file manipulation, password changes, reverse shells, or data theft. The attack requires root credentials but enables full control over the device remotely.

Compliance Impact

This vulnerability enables remote code execution on the Ziroom ZHOME device, which could allow unauthorized access to sensitive data. For GDPR, this may lead to unauthorized processing or disclosure of personal data, violating principles of data protection and user rights. Under HIPAA, if the device handles protected health information, this flaw could result in unauthorized access or disclosure, breaching security requirements for electronic protected health information.

Mitigation Strategies

Disable HTTP Basic Authentication for root access. Update firmware to a patched version if available. Restrict network access to the device via firewall rules. Monitor for unusual command execution patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101264. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart